For on-premises SharePoint Server, patch every farm server with the update that matches its edition, include the required language-pack updates for SharePoint Server 2016 and 2019, then rotate ASP.NET machine keys and restart IIS across the farm. Verify patch status and possible compromise separately: a successful update does not prove that an attacker who accessed the farm earlier has been removed. Microsoft says SharePoint Online in Microsoft 365 is not affected by CVE-2025-53770 or CVE-2025-53771.
What ToolShell affects—and what it does not
Microsoft described active attacks in July 2025 against on-premises SharePoint Server involving CVE-2025-53770 and CVE-2025-53771, related to the earlier CVE-2025-49704 and CVE-2025-49706. In Microsoft’s threat-intelligence description, CVE-2025-53770 is the remote-code-execution vulnerability, while CVE-2025-53771 is a security-bypass/path-traversal vulnerability. Microsoft’s guidance says these vulnerabilities affect on-premises SharePoint Server; SharePoint Online in Microsoft 365 is not impacted.
The active-attack reporting describes the situation when Microsoft published its guidance in July 2025. It does not establish the exploitation status on October 4, 2026. Treat the incident as a reason to check your environment and current Microsoft guidance, not as evidence that attacks are happening now.
Which SharePoint update applies to your farm?
Use the package path for the installed SharePoint Server edition, not a KB number chosen from another edition. The following are the July 2025 security updates and builds identified in Microsoft guidance; they are not confirmation that no later update has superseded them. Before deployment, check Microsoft’s current update guidance against the farm’s edition, language packs, and servicing state.
#1 Best Overall
| Installed edition | July 2025 security update | Build identified by Microsoft Support | Additional language-pack update |
|---|---|---|---|
| SharePoint Server Subscription Edition | KB5002768 | 16.0.18526.20508 | Not stated for this package in the cited guidance |
| SharePoint Server 2019 | KB5002754 | 16.0.10417.20037 | KB5002753; Microsoft says to install both updates |
| SharePoint Server 2016 | KB5002760 | 16.0.5513.1001 | KB5002759 |
Microsoft’s support articles describe these KBs as addressing SharePoint Server remote-code-execution and spoofing vulnerabilities and refer to CVE-2025-53770 and CVE-2025-53771. The build numbers identify the packages documented in those articles; use Microsoft’s live guidance to confirm what is applicable to a farm being serviced now.
Patch the farm and complete the required follow-up
Plan the change across the whole SharePoint farm. Applying an update to only one server, or installing a package without its required companion update, leaves the patch state incomplete.
Rank #2
- Inventory the farm. Record every SharePoint server, its edition and installed build, the language packs present, and its current servicing state. Match each server to Microsoft’s currently applicable update instructions.
- Install the edition-specific security update. Apply the appropriate Microsoft package to the farm. Microsoft’s advisory describes the security updates as cumulative. For SharePoint Server 2016 and 2019, install both updates listed for the edition, including the language-pack update.
- Check AMSI and antivirus coverage. Confirm that Antimalware Scan Interface (AMSI) is enabled and correctly configured on each applicable server. Where HTTP Request Body scanning is available, Microsoft recommends Full Mode and Defender Antivirus on all SharePoint servers. AMSI integration was enabled by default in the September 2023 security update for SharePoint Server 2016 and 2019, and in the SharePoint Subscription Edition 23H2 feature update; verify the actual farm configuration rather than relying on those defaults. If AMSI cannot be enabled, Microsoft’s guidance recommends disconnecting the server from the internet until it is updated. If disconnection is not possible, restrict unauthenticated access through an authenticated VPN, proxy, or gateway.
- Rotate the ASP.NET machine keys. Microsoft’s PowerShell guidance names
Set-SPMachineKey -WebApplication <SPWebApplicationPipeBind>to generate a key andUpdate-SPMachineKey -WebApplication <SPWebApplicationPipeBind>to deploy it. Run the commands in accordance with Microsoft’s instructions for the relevant web applications and record completion. - Restart IIS on every SharePoint server. After key rotation, Microsoft’s instructions specify
iisreset.exeon each SharePoint server. Track completion server by server; restarting only one machine is not a farm-wide restart. - Maintain detection coverage. Deploy Defender for Endpoint or an equivalent solution to detect and block post-exploitation activity. This is a detection and protection layer, not a replacement for installing the SharePoint update.
Verify patch state separately from compromise state
“Patched” and “not compromised” are different conclusions. Keep separate records for package installation and post-update actions, and for the results of your security investigation.
Patch-state checks
- For every farm server, compare its edition, installed build, and update inventory with the applicable Microsoft update documentation. For 2016 and 2019, confirm the language-pack update as well as the primary update.
- Confirm and record farm-wide completion of machine-key rotation and the IIS restart on every SharePoint server.
- Verify AMSI configuration, HTTP Request Body Full Mode where available, and antivirus coverage rather than assuming those controls are enabled.
- Where available, review Microsoft Defender Vulnerability Management exposure and remediation status, including Evidence of Exploitation tags. Visibility depends on the organization’s Defender capabilities and available telemetry; an absence of a tag is not proof that the farm was never exploited.
Compromise checks
- Review Defender Antivirus detections and Defender for Endpoint alerts identified in Microsoft’s guidance. Relevant alert types include possible web-shell installation, possible exploitation of SharePoint vulnerabilities, suspicious IIS worker behavior, and suspicious .NET assembly loading. Microsoft cautions that alerts can also arise from unrelated activity, so investigate rather than treating an alert alone as proof.
- Hunt across IIS, SharePoint ULS, Windows event, PowerShell, and available Sysmon logs. The Cyber Security Agency of Singapore’s July 24, 2025 guide highlights POST requests to
/_layouts/15/ToolPane.aspx?DisplayMode=Editwith aRefererof/_layouts/SignOut.aspx, later requests to web shells such asspinstall0.aspx, and suspicious files in SharePointTEMPLATELAYOUTSdirectories. Treat these as indicators to investigate, not standalone proof of compromise. - Use Microsoft’s Advanced Hunting guidance with a historical window suitable for the investigation. Its examples cover up to 30 days of events; available history depends on telemetry retention and the tools configured in your organization. Preserve relevant evidence and assess the full farm and connected environment, not just the server where an alert first appeared.
If the farm may have been compromised
A server compromised before patching may remain compromised after the update. Patching closes the vulnerability addressed by the update; it does not establish that an attacker has lost access, that a web shell or other persistence has been removed, or that connected systems are safe.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
- Use an incident-response process. Identify and scope suspicious activity, contain affected systems, and preserve relevant evidence before changes that could destroy it.
- Remove persistence and investigate the environment. Address web shells and other attacker footholds, then assess the wider farm and connected systems. Do not treat clean patch inventory as evidence that this work is complete.
- Recover from a trusted state when necessary. The Cyber Security Agency of Singapore’s guidance says patching alone is insufficient for an already-compromised environment and describes rebuilding or restoring from a verified clean backup as recovery options. Choose recovery actions based on the investigation and the integrity of the available backup.
If indicators point to compromise, involve your organization’s incident-response team or qualified SharePoint recovery support. Coordinate containment and recovery with the teams responsible for the farm and connected infrastructure.
Quick Recap
Best Value
Rank #4
What a completed verification should document
- The edition, build, applicable update packages, and language-pack update status for every farm server.
- Completion of machine-key rotation and the post-rotation IIS restart on every SharePoint server.
- AMSI, scanning-mode where available, and antivirus coverage checks.
- The alert, log, hunting, and filesystem review performed, the time window covered, and any findings that require containment or recovery.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




